Skip to main content

Company · Trust

Controls you can check, outside the model.

Mandates, review rules and limits run on the server, before any payment is sent. Every settled spend gets a signed receipt. The audit trail records every governed action.

Mandate · mnd_22sh_v2 demo
agentagt_22sh · Shop assistant
principalAurora Store Ltda · verified
scopecompute · APIs · suppliers
limit per transactionR$ 3,000
hard budgetR$ 20,000 / month
expiryDec 31, 2026 · revocable
Request · R$ 4,200.00 · Nimbus Cloudchecked on the server, not by the modelcheckingheld for review
Receipt · rec_951ced25519:9f2c…7ab1 · anyone can verifyverified

Sandbox run · demo data

What a mandate carries

A signed spend authority: cap, scope, expiry.

The agent

Which agent may spend under it. Each agent has its own mandate.

The principal

The organization the agent acts for, verified before production.

The scope

Cap per payment, hard budget, allowed recipients and methods, and an expiry. A boleto above the cap per payment waits for a person.

The expiry

When the authority ends. A mandate can be revoked at any time.

Controls

What runs before money moves.

Server-side checks

Every request is checked against the mandate on the server, not by the model.

Review rules

Requests matching your approval rules wait for review; requests outside hard limits are blocked.

Revocation

Revoke a mandate and the agent's new payments stop.

Verified approverrolling out

The approver's identity checked before a decision counts.

Records

Two records, kept apart.

Signed receipt

Every settled spend gets a signed receipt anyone can verify.

Audit trail

Every governed action is recorded in the audit trail: proposals, decisions, payments and refunds.

Audit export

Every payment leaves a signed receipt. Export the audit trail as JSON with a signed manifest.

Data and keys

What we hold, and how keys are split.

Keys per environment

Test and live keys are separate. Test mode never moves real money.

Agents hold no credentials

Agents call CodeSpar with a key; they never hold bank or card credentials.

Card handlingrolling out

Your agent never holds a card number. Card storage is rolling out with production.

Limits and contact

What this page does not claim.

Certifications

No certification is claimed on this page until it is completed and published.

Responsible disclosure

Report security issues to security@codespar.dev.

Who operates the money

CodeSpar provides software to organize payments initiated by agents. It is not a bank or a payment institution, holds no authorization of its own from the Central Bank of Brazil to provide the account and Pix services described here, and does not act on behalf of Celcoin.

For enabled customers, BRL payment accounts are opened and maintained at Celcoin Instituicao de Pagamento S.A., CNPJ 13.935.893/0001-09, code 509, an institution authorized and supervised by the Central Bank of Brazil. Celcoin provides the regulated services on this route; CodeSpar provides the interface and software integration.

Celcoin accounts and services must not be used to carry out or facilitate cryptocurrency transactions, betting operators' activities, unlawful international remittances or other unlawful activities. The USDC/x402 route presented by CodeSpar is separate from the Celcoin BRL/Pix account route. Its presentation does not authorize cryptocurrency transactions through Celcoin accounts.

Questions, requests and complaints: hello@codespar.dev. For account or Pix issues not resolved through initial support, see Celcoin's official channels: https://www.celcoin.com.br/contato-celcoin/. After prior support, see Celcoin's Ombudsman: https://www.celcoin.com.br/ouvidoria/.

Give your agents a way to pay and get paid.

Build is free: hosted MCP, SDK and sandbox.

Test keys are free.

terminal · test modedemo
$ claude mcp add --transport http codespar \ https://connect.codespar.dev/mcp> "revoke mnd_22sh_v2" mandate revoked · new payments from agt_22sh stop recorded in the audit trail existing receipts stay verifiable

Sandbox run · demo data

CodeSpar · Trust